Microsoft SMBv1 Remote Code Execution Vulnerability

The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

Published 9 Sep 2026Updated 9 Sep 2026174 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.

Affected versions

SMBv1: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 41891Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)Sean Dillon2017-04-17VerifiedExploit-DB 47456DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)Metasploit2019-10-02VerifiedExploit-DB 42031Microsoft Windows 7/2008 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)sleepya2017-05-17VerifiedExploit-DB 42315Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)sleepya2017-07-11VerifiedExploit-DB 42030Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)sleepya2017-05-17VerifiedExploit-DB 41987Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)Juan Sacco2017-05-10VerifiedPoC-in-GitHub · peterpt/eternal_scannerAn internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)★ 339peterpt2017-07-16CandidatePoC-in-GitHub · kimocoder/eternalblueCVE-2017-0144★ 1kimocoder2019-06-02CandidatePoC-in-GitHub · EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution★ 18EEsshq2021-03-22CandidatePoC-in-GitHub · quynhold/Detect-CVE-2017-0144-attackChương trình theo dõi, giám sát lưu lượng mạng được viết bằng Python, nó sẽ đưa ra cảnh báo khi phát hiện tấn công CVE-2017-0144★ 0quynhold2022-12-16CandidatePoC-in-GitHub · ducanh2oo3/Vulnerability-Research-CVE-2017-0144LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB.★ 0ducanh2oo32024-04-03CandidatePoC-in-GitHub · AnugiArrawwala/CVE-ResearchCVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523★ 0AnugiArrawwala2024-07-03CandidatePoC-in-GitHub · denuwanjayasekara/CVE-Exploitation-ReportsCVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708★ 0denuwanjayasekara2024-09-11CandidatePoC-in-GitHub · sethwhy/BlueDoorCan you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privileges and locate the flag stored behind the windows security★ 2sethwhy2024-12-21CandidatePoC-in-GitHub · AtithKhawas/autoblueAutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only!★ 4AtithKhawas2024-12-30CandidatePoC-in-GitHub · MedX267/EternalBlue-Vulnerability-ScannerThis script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.★ 1MedX2672025-02-03CandidatePoC-in-GitHub · pelagornisandersi/WIndows-7-automated-exploitation-using-metasploit-framework-Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell.★ 0pelagornisandersi2025-05-30CandidatePoC-in-GitHub · luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144★ 0luckyman29072025-06-25CandidatePoC-in-GitHub · AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-EndpointThis report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a Windows 10 machine within a finance-oriented infrastructure.★ 15AdityaBhatt30102025-07-10CandidatePoC-in-GitHub · FireTemple/Blackash-CVE-2017-0144CVE-2017-0144★ 1FireTemple2025-11-27CandidatePoC-in-GitHub · Mitsu-bis/Eternal-Blue-CVE-2017-0144-THM-Write-UpThe SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability."★ 0Mitsu-bis2025-12-16CandidatePoC-in-GitHub · klairmanraj/Multi-VLAN-Enterprise-Network-Security-InfrastructureMulti-VLAN virtual network across 10 VMs: GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, Kea DHCP, Docker web services, SMB file sharing. Vulnerability assessment using OWASP ZAP (Stored XSS) and Nessus (CVE-2017-0144 EternalBlue). Validated with Wireshark.★ 0klairmanraj2026-04-20CandidatePoC-in-GitHub · klairmanraj/Vulnerability-Risk-Assessment-TVRA-Enterprise-NetworkQualitative TVRA for a multi-VLAN enterprise lab: Stored XSS on WebGoat (HIGH, 16), Stored XSS on Magento (ABSENT, MEDIUM, 8), and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25). Scored via Likelihood × Impact using CVSS v3.0 and ZAP/Nessus/Wireshark evidence.★ 0klairmanraj2026-04-20CandidatePoC-in-GitHub · klairmanraj/Multi-VLAN-Enterprise-Network-Vulnerability-AssessmentProfessional vulnerability assessment of a multi-VLAN enterprise network (student21.local). Confirmed Stored XSS on WebGoat (HIGH, 16) via OWASP ZAP fuzzer, absent XSS on Magento via server sanitization, and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25) via Nessus + Wireshark PCAP validation.★ 0klairmanraj2026-04-20CandidatePoC-in-GitHub · dannic145/EternalBlue-Exploit-DemonstrationCybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.★ 0dannic1452026-04-22CandidatePoC-in-GitHub · ichhyak22/EternalBlue-Exploit-Demonstration-MS17-010Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.★ 0ichhyak222026-04-23CandidatePoC-in-GitHub · trinadh-dasari-cyber/eternalblue-ms17-010-researchControlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK mapping★ 0trinadh-dasari-cyber2026-05-13CandidatePoC-in-GitHub · 0xBlackash/CVE-2017-0144CVE-2017-0144★ 20xBlackash2026-06-14CandidatePoC-in-GitHub · probablysecure/Triage-CVE-2017-0144Goal is to triage well known attacks and learn how security teams quickly respond.★ 0probablysecure2026-06-29CandidatePoC-in-GitHub · KitSkater/legacyshield-CVE-2017-0144Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack detection, automated firewall response, configuration auditing, and security reporting for legacy and unsupported systems.★ 0KitSkater2026-07-19CandidatePoC-in-GitHub · quincyomoruyi6-lang/BLUE-WRITEUP-CVE-2017-0144Conducted a complete security assessment of an unpatched Windows 7 target ("Blue") to demonstrate the impact of legacy service vulnerabilities in an enterprise environment★ 1quincyomoruyi6-lang2026-09-10CandidatePoC-in-GitHub · porcumarcooo/TryHackMe-Blue-MS17-010Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).★ 0porcumarcooo2026-09-10Candidate